Die durchkommenden Emails haben aber u.a. Einwahl-IP's als Absender.
May 2 14:10:34 h****** greylist[3977]: new message: xnnkx@temporarytattoos.com -> adresse@meinedomain.tld (65.40.37.134)
May 2 14:10:34 h****** greylist[3977]: status: blocked; reason: triplet doesn't exist, greylisted for 5 minutes
...
May 2 14:20:40 h****** greylist[5670]: new message: xnnkx@temporarytattoos.com -> adresse@meinedomain.tld (65.40.37.134)
May 2 14:20:40 h****** greylist[5670]: status: passed; reason: triplet exists and block has already expired; id: 78432
May 2 14:20:41 h****** spamd[9359]: spamd: connection from meinedomain.tld [127.0.0.1] at port 38110
May 2 14:20:41 h****** spamd[9359]: spamd: processing message <001501c78cb4$466eb1d0$5d36d696@ltjz> for qmaild:0
May 2 14:20:41 h****** spamd[9359]: spamd: identified spam (13.0/5.0) for qmaild:0 in 0.4 seconds, 3877 bytes.
May 2 14:20:41 h****** spamd[9359]: spamd: result: Y 12 - BAYES_99,HELO_DYNAMIC_IPADDR,RCVD_IN_BL_SPAMCOP_NET scantime=0.4,size=3877,user=qmaild,uid=0,required_score=5.0,rhost=meinedomain.tld,raddr=127.0.0.1,rport=38110,mid=<001501c78cb4$466eb1d0$5d36d696@ltjz>,bayes=1,autolearn=no
May 2 14:20:41 h****** qsheff[5674]: new message: xnnkx@temporarytattoos.com -> adresse@meinedomain.tld (65.40.37.134)
May 2 14:20:41 h****** qsheff[5674]: clamav status: clean
May 2 14:20:41 h****** spamd[5323]: prefork: child states: II
May 2 14:20:41 h****** qmail: 1178108441.670712 new msg 8592614
May 2 14:20:41 h****** qmail: 1178108441.670925 info msg 8592614: bytes 7051 from <xnnkx@temporarytattoos.com> qp 5677 uid 2020
May 2 14:20:41 h****** qmail: 1178108441.677993 starting delivery 218: msg 8592614 to local 1-adresse@meinedomain.tld
May 2 14:20:41 h****** qmail: 1178108441.678298 status: local 1/10 remote 0/20
May 2 14:20:41 h****** qsheff[5674]: QUEUE, queue=q1178108440-883752-5674, recvfrom=65.40.37.134, from='xnnkx@temporarytattoos.com', to='adresse@meinedomain.tld', subj='{SPAM} has full ownership of and takes sole responsibility for all content.', size=6904
May 2 14:20:41 h****** qmail: 1178108441.772977 delivery 218: success: did_1+1+1/qp_5682/
May 2 14:20:41 h****** qmail: 1178108441.773082 status: local 0/10 remote 0/20
May 2 14:20:41 h****** qmail: 1178108441.773144 end msg 8592614
AN ALLE FINANZINVESTOREN!
DIESE AKTIE WIRD DURCHSTARTEN!
MITTWOCH 2. MAG STARTET DIE HAUSSE!
Company: ORAMED PHARMA
WKN : A0J3FG
ISIN : US68403P1049
Markt: Frankfurt
DER INVESTORALARM! OJU.F BEGINNT HOCHGEHEN! DONNERSTAG 3. MAG STARTET
DIE HAUSSE!
Company: ORAMED PHARMA
WKN : A0J3FG
ISIN : US68403P1049
Markt: Frankfurt
body MYRULE_TradingDE /AN ALLE FINANZINVESTOREN|DER INVESTORALARM|ORAMED PHARMA/
score MYRULE_TradingDE 10.0
Vorschau der "Spam": DER INVESTORALARM! OJU.F BEGINNT HOCHGEHEN! DONNERSTAG 3.
MAG STARTET DIE HAUSSE! Company: ORAMED PHARMA WKN : A0J3FG ISIN : US68403P1049
Markt: Frankfurt Kurzel : OJU.F Letztr Kurs: 0.477 4 Tages Prognose: 2.15
[...]
Inhaltsanalyse im Detail: (19.8 Punkte, 5.0 benötigt)
Pkte Regelname Beschreibung
---- ---------------------- --------------------------------------------------
4.2 HELO_DYNAMIC_IPADDR Relay HELO'd using suspicious hostname (IP addr
1)
7.2 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
[score: 1.0000]
2.4 RCVD_IN_WHOIS_BOGONS RBL: CompleteWhois: sender on bogons IP block
[113.121.30.115 listed in combined-HIB.dnsiplists.completewhois.com]
2.0 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP address
[72.72.219.184 listed in dnsbl.sorbs.net]
3.9 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL
[72.72.219.184 listed in sbl-xbl.spamhaus.org]
Was sollen eigentlich diese Aktien Spam?
.... Vor allem haben die Spammer nichts direkt davon, oder doch?
Gibt es einen anderen Sinn?
May 2 10:52:30 server4 postgrey: delayed 608 seconds: client=125.234.68.117, from=asunc@ccsi.com
May 2 10:54:07 server4 postgrey: delayed 602 seconds: client=host-216-220-114-11.dsl.bway.net, from=rfwkh@bellehaven.com,
May 3 21:12:27 server4 postfix/smtpd[819]: NOQUEUE: reject: RCPT from CBL217-132-70-174.bb.netvision.net.il[217.132.70.174]: 554 5.7.1 Service unavailable; Client host [217.132.70.174] blocked using dynablock.njabl.org; Dynamic/Residential IP range listed by NJABL dynablock - http://njabl.org/dynablock.html; from=<shop@xxxx> to=<xxxx@xxxx> proto=SMTP helo=<CBL217-132-70-174.bb.netvision.net.il>
oder
May 3 21:15:09 server4 postfix/smtpd[819]: NOQUEUE: reject: RCPT from clt-84-32-253-83.vdnet.lt[84.32.253.83]: 450 4.7.1 <HOME-01.dtiltas.lt>: Helo command rejected: Host not found; from=<inroads@xxxx> to=<xxxx@xxxxx> proto=ESMTP helo=<HOME-01.dtiltas.lt>
May 4 00:32:04 h****** greylist[28056]: status: passed; count: 671; reason: triplet exists and block has already expired; id: 21321
May 4 00:38:21 h****** greylist[28353]: status: passed; delay: 00:10:17; reason: triplet exists and block has already expired; id: 79055
postgrey 14605 0.0 0.2 10624 8108 ? Ss May03 0:01 /usr/sbin/postgrey --pidfile=/var/run/postgrey.pid --daemonize --inet=127.0.0.1:60000 --delay=900 --retry-window=37h --auto-whitelist-clients=5 --greylist-text=.....
May 4 08:16:13 server4 postfix/smtpd[17091]: NOQUEUE: reject: RCPT from static.88-198-38-73.clients.your-server.de[88.198.38.73]: 450 4.7.1 <server.bragadin.
com>: Helo command rejected: Host not found; from=<....@studienservice.de> to=<.........> proto=ESMTP helo=<server.bragadin.com>
We use essential cookies to make this site work, and optional cookies to enhance your experience.